IBM has disclosed 22 vulnerabilities affecting DataStage on Cloud Pak for Data 5.4.0.0. The supplied report identifies eight CVEs, including CVE-2026-16346, rated 9.9 on CVSS v3, and says the wider set includes one critical and seven high-severity flaws. The issues could allow authenticated remote attackers to execute arbitrary commands, cause denial of service, access files or intercept credentials. No active exploitation or public proof-of-concept exploits has been confirmed.
The reported weaknesses include OS command injection, path traversal during archive extraction and TLS certificate validation problems. CVE-2026-17102 and CVE-2026-81545 allegedly allow attackers to inject commands, while CVE-2026-84421 could enable access to or overwriting of restricted files.
The report also describes a cross-tenant credential exposure issue, in which a shared, unrotated master key could allow an authenticated user to recover other tenants’ connection passwords, Git personal access tokens and IAM API keys. It further says CVE-2026-84418 could let an attacker use a forged certificate to capture an IAM bearer authorisation header.
IBM recommends upgrading DataStage on Cloud Pak for Data to version 5.4 patch 7 or later, following its official upgrade instructions. The report presents this as the remediation for all 22 vulnerabilities and urges administrators not to delay, despite there being no confirmed exploitation.